Skip to main content
Category: SOC Reporting

Restricted Use Report

Also known as: Restricted-Use Report, Report Restricted as to Use
Simply put

A restricted use report is an auditor's report whose distribution and use are limited to specific parties named or identified in the report, rather than being available to the general public. It alerts readers that the report is not intended for anyone outside those specified users, because it addresses matters relevant only to those parties. SOC 2 Type I and Type II reports are typically issued as restricted use reports intended for the service organization, its user entities, and other knowledgeable parties.

Formal definition

A restricted use report is an attestation or audit report in which the practitioner adds language limiting the intended use to identified parties, indicating that the report is not intended to be, and should not be, used by anyone other than those specified users. Restriction is applied when the subject matter or criteria are suitable only for parties who understand them, or when the report addresses matters relevant to particular users. SOC 2 examinations performed under the AICPA's attestation standards (SSAE 18) generally result in restricted use reports intended for the service organization's management, user entities, and parties with sufficient knowledge of the system and controls; this distinguishes them from SOC 3 reports, which are general use. The historical guidance on restricting report use in AU Section 532 has been superseded in the AICPA clarified standards, and the concept of restricted use remains embedded in current attestation reporting practice. The restriction affects distribution only and does not narrow the scope of the controls or period covered by the underlying examination.

Why it matters

The restricted use designation on a SOC 2 report is a defining feature of how these examinations are shared and consumed. Because SOC 2 Type I and Type II reports are typically issued as restricted use reports, they are intended only for the service organization, its user entities, and other parties with sufficient knowledge of the system and controls to interpret them correctly. This matters because the detailed contents of a SOC 2 report, including descriptions of controls, test procedures, and results, are meaningful only to readers who understand the system context. Distributing such a report to the general public or to parties without that context risks misinterpretation of what the report does and does not convey.

For compliance managers and auditors, understanding the restriction is essential to managing report distribution appropriately. A restricted use report cannot serve the marketing or public-assurance function that a general use report provides; that is the role of a SOC 3 report, which is designed for general distribution. Confusing the two, or sharing a restricted use SOC 2 report beyond its intended audience, can create both practical and professional complications. The restriction is a statement about intended audience, not a limitation on the rigor of the underlying examination.

It is important to remember that the restriction affects distribution only and does not narrow the scope of the controls or the period covered by the underlying examination. A SOC 2 report attests solely to the controls and period it covers and does not guarantee freedom from breaches; the restricted use language governs who may rely on the report, not the assurance the examination provides.

Who it's relevant to

Compliance and GRC Managers
Those responsible for sharing a SOC 2 report with customers and prospects need to understand that Type I and Type II reports are typically restricted use, intended for the service organization, its user entities, and other knowledgeable parties. When broad public distribution is desired, a SOC 3 report, designed for general use, is generally the appropriate vehicle rather than a restricted use SOC 2 report.
Service Organization Management
As a named intended user, management should recognize that the restriction governs distribution of the report, not the scope of the examination or the period covered. The report addresses matters relevant to specified parties who understand the system and controls, and it should not be redistributed to recipients outside that intended audience.
User Entities and Their Auditors
User entities relying on a service organization's SOC 2 report are typically among the identified parties permitted to use it, provided they have sufficient knowledge of the system and controls to interpret the results. They should note that the report attests only to the controls and period covered and does not guarantee freedom from breaches.
Practitioners and CPA Firms
The licensed CPA firms performing SOC 2 examinations under SSAE 18 apply the restricted use language in accordance with current AICPA clarified attestation reporting practice. They determine when restriction is appropriate based on the suitability of the subject matter and criteria for the intended users.

Inside Restricted Use Report

Restricted Use Legend
An explicit paragraph in the report stating that its use is limited to specified parties. In a SOC 2 examination, this restriction typically identifies management of the service organization, user entities during the period covered, and their auditors as the intended users, rather than the general public.
Intended Users
The defined set of parties who possess sufficient understanding of the service organization, the nature of the engagement, and the applicable Trust Services Criteria to interpret the report appropriately. SOC 2 Type I and Type II reports are typically restricted-use documents directed at these knowledgeable parties.
Basis for Restriction
The professional-standards rationale for limiting distribution. Under AICPA attestation guidance, restriction is appropriate when the subject matter or criteria are suitable only for parties with specific knowledge. The clarified standard addressing restricted-use reports is AU-C Section 905, which superseded the earlier AU Section 532 referenced under prior guidance.
Distinction from General Use Reports
Restricted-use reports contrast with general-use reports such as a SOC 3 report, which is designed for broad distribution and does not carry the same distribution restriction because it omits the detailed description of tests and results.

Common questions

Answers to the questions practitioners most commonly ask about Restricted Use Report.

Does a restricted use report mean the report is a certification that can be shown to anyone as proof of compliance?
No. A restricted use report is not a certification, and its restriction is precisely about who may rely on it. A SOC 2 report is an attestation examination performed by a licensed CPA firm, not a certificate, and a restricted use designation limits distribution and reliance to specified parties. It is not intended for broad, general distribution as public proof of compliance. Where a freely distributable summary is needed, a SOC 3 report is typically the more appropriate deliverable, since it is a general use report.
Is a restricted use report unique to SOC 2, or does the concept apply more broadly?
The restricted use concept is not unique to SOC 2. It is a feature of attestation and audit reporting under AICPA standards generally, applied when a report's subject matter, criteria, or intended reliance make it appropriate only for specified parties. SOC 1 and SOC 2 Type I and Type II reports are commonly issued as restricted use, while SOC 3 reports are designed for general use. ISO/IEC 27001 outcomes are a separate matter entirely: they result in a certification issued by an accredited certification body, not an attestation report, so the restricted use framing does not apply to them in the same way.
Which professional standard governs restricted use language in these reports?
Restricted use paragraphs in AICPA attestation and audit reporting are addressed by the clarified standards, with AU-C Section 905 governing alert language that restricts the use of a report to specified parties. Practitioners may encounter older references to the superseded AU Section 532, but the current clarified guidance should be relied upon. The exact wording and applicability depend on the engagement type and the practitioner's judgment, so the specific standard and phrasing are best confirmed with the CPA firm performing the examination.
Who are typically considered the specified parties permitted to rely on a restricted use SOC 2 report?
The specified parties generally include the service organization's management, and often its user entities (customers) and their auditors, depending on how the report defines its intended users. The precise list is determined during scoping and stated within the report itself. Because reliance is limited to those parties, organizations receiving a SOC 2 report should confirm they fall within the defined intended users before relying on it, and should not assume that a report addressed to other parties extends reliance to them.
How should a vendor respond when a prospective customer who is not a specified party requests a restricted use report?
In most engagements, the vendor can share the restricted use report with a prospective customer under a non-disclosure agreement once that party is appropriately brought within the intended user relationship, though practices vary and the CPA firm's guidance should be followed. Alternatively, a SOC 3 report, which is designed for general use, can be provided when broad distribution is needer. The appropriate path depends on the nature of the relationship and the report's stated restrictions, so confirming the approach with the service auditor is advisable.
Does receiving a restricted use SOC 2 report guarantee the service organization has no security incidents?
No. A SOC 2 report attests only to the controls and, for a Type II, the review period covered by the examination; it does not guarantee freedom from breaches or provide assurance beyond its defined scope and period. The restricted use designation governs who may rely on the report, not the strength of the assurance. Readers should evaluate the scope, the Trust Services Criteria selected, the review period, and any noted exceptions rather than treating the report as a blanket guarantee of security.

Common misconceptions

A restricted use SOC 2 report can be freely posted publicly or handed to any prospective customer as marketing material.
The report is intended only for the specified parties identified in the restriction, typically management, user entities during the covered period, and their auditors. For broad or public distribution, a general-use SOC 3 report is generally the more appropriate deliverable, depending on scope.
The restricted use designation means the report is confidential in a legal sense or reflects weaker assurance than an unrestricted report.
The restriction reflects that the subject matter and criteria are intended for parties with sufficient knowledge to interpret them, not a difference in the rigor of the examination. It is a communication and appropriate-use control, not a statement about the quality of the underlying work.
A restricted use SOC 2 report is a certification that can be shared as proof of compliance with any framework.
A SOC 2 report is an attestation examination performed by a CPA firm under AICPA attestation standards, not a certification. It attests only to the controls and, for a Type II, the operating effectiveness over the defined review period, and does not automatically satisfy other frameworks such as ISO 27001.

Best practices

Confirm before distribution that each recipient falls within the intended-user population defined in the report's restriction paragraph, typically management, user entities during the covered period, and their auditors.
When broad or public distribution is needed, request a general-use SOC 3 report rather than sharing the restricted-use SOC 2 report outside its intended audience.
Reference the current clarified attestation guidance, AU-C Section 905, when documenting the basis for a restricted-use report, rather than the superseded AU Section 532.
Review the restriction language with the CPA firm during scoping to ensure the specified parties align with how the organization intends to use and share the report.
Communicate to internal stakeholders and sales teams that the restricted-use report cannot be treated as public marketing material, and establish an approval process for release to third parties.
Remember that the report attests only to the controls and the period covered and does not guarantee freedom from breaches, so avoid representing it as broader assurance than its defined scope supports.